MALICIOUS — jefugigibubowedevemavuz.pdf
MALICIOUS — jefugigibubowedevemavuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2a34e6c8fa58934e757ecbb0c2db63d713e0296e4d2b2900b953385809e84584 - SHA-1:
e8a8316630eec7c55abb2a99f745c11b8b34b472 - MD5:
41d9dd156b19ee82174623a3ad3527d8 - ssdeep:
1536:5cfPfIuOiAYZE2qjtwfOehiQrX0tGa1W0CaVHaUSkcWapOtQlINkVQ1PC/5r2:JXXIE2qj7eUQrXrSCeHrfNtQl7QL - TLSH:
T1EF38B0F3606FED8DB78FAB07A49A245C6086E3C43162EA504089F57C95BC57E7F24910 - Submitted as: jefugigibubowedevemavuz.pdf
- File type: pdf · Size: 78200 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://xn--365-pn7mwb654m2qn.com/ckupload/files/59033056342.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://greensquares.in/userfiles/file///tizobawumogojobejujotidom.pdf, http://christopherspubandgrille.com/userfiles/files/zuroxonokaxisobemoxokasiw.pdf, http://jyjwqj.com/uploadfile/file///2021090517143751.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=morning+surya+namaskar+mantra
- http://greensquares.in/userfiles/file///tizobawumogojobejujotidom.pdf
- http://christopherspubandgrille.com/userfiles/files/zuroxonokaxisobemoxokasiw.pdf
- http://jyjwqj.com/uploadfile/file///2021090517143751.pdf
- https://psychotherapie-dr-albrecht.de/wp-content/plugins/formcraft/file-upload/server/content/files/161352d12497bb---79885376167.pdf
- http://nilesk.com/userfiles/file/95423523093.pdf
- http://xn--365-pn7mwb654m2qn.com/ckupload/files/59033056342.pdf
- http://galantemontagnana.it/ckfinder/userfiles/files/kakesirinonemakudakep.pdf
- http://gmkms.net/upfile_editor/2021/files/kopotiwigor.pdf
- https://goldenlinejsc.com/userfiles/file/fojopelavirokibozu.pdf
- https://i-chat.tw/js/ckfinder/userfiles/files/94668455720.pdf
- http://klawiatury-foliowe.pl/_data/file/fovuxoginezenoma.pdf
- http://www.ddd-iasi.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16155637c1df8e---44974894972.pdf
- http://brlairport.com/images/file/72305616865.pdf
- https://tbsva.org/Upload/files/20210919160117.pdf
- http://stcforanebanglore.smcim.com/www/js/ckfinder/userfiles/files/43299604910.pdf
- https://www.golddustdental.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613a8ad7118d3---66809948115.pdf
- http://studiocalcinoni.com/userfiles/files/waxex.pdf
- http://vhshf.de/File/navixuwobexujosabidu.pdf
- https://aviseco.ro/userfiles/file/18638460210.pdf
- http://jilienjrubin.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/49542581953.pdf
- https://www.sacproblemleri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613b739bee359---zibigifabijoduligakalanij.pdf
- http://szjwwj.com/userfiles/file///kitupanabemene.pdf
- http://robertwestlaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/kasutonuzepirepopadi.pdf
- https://zevkotodoseme.com/upload/ckfinder/files/tadarorixumasiw.pdf
Embedded domains
- feedproxy.google.com
- greensquares.in
- christopherspubandgrille.com
- jyjwqj.com
- psychotherapie-dr-albrecht.de
- nilesk.com
- xn--365-pn7mwb654m2qn.com
- galantemontagnana.it
- gmkms.net
- goldenlinejsc.com
- i-chat.tw
- klawiatury-foliowe.pl
- brlairport.com
- tbsva.org
- stcforanebanglore.smcim.com
- www.golddustdental.com
- studiocalcinoni.com
- vhshf.de
- jilienjrubin.com
- www.sacproblemleri.com
- szjwwj.com
- robertwestlaw.com
- zevkotodoseme.com
- imhkayseri.com
- www.w3.org
File paths
- F:\zDvh
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report